Format: Panel · Required preknowledge: Intermediate · Room: EG08
Time: 11:00–12:00
Topics: Data Protection & Privacy, Cybersecurity, AI Governance
Buying AI means inheriting risk. Every procurement decision triggers a cascade of legal and compliance obligations that organizations must address systematically before the contract is signed. This is the groundwork for a sound and reliable AI inventory. Speakers will map the risk assessment framework that any responsible AI procurement process requires: GDPR and data protection obligations tied to the AI system’s data flows; cybersecurity requirements under the EU AI Act and the Cyber Resilience Act; AI Act compliance duties from risk classification to conformity assessments; and IP risks arising from vendor use of input data for training purposes and licensing terms concerning AI-generated output. This session explores how to build a structured vetting process across each of these risk dimensions and what challenges organizations face in practice.
Speakers: Jenny Le, Ricarda Neukam, Taina Baylao, Amela Gjishti